CVE-2018-0665 - CVE House
Back to Database
Status published Medium CVE-2018-0665

Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier,...

Vulnerability Description

Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0666.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-0665

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Yamaha Corporation

View all reports →

Affected Software

Yamaha Broadband VoIP Router RT57i, Yamaha Broadband VoIP Router RT58i, Yamaha Broadband VoIP Router NVR500, Yamaha Gigabit VPN Router RTX810, Yamaha Firewall FWX120, Biz Box Router N58i, N500, NVR500, and RTX810, Biz Box Router N58i, and N500
Vulnerable Versions:
Rev.8.00.95 and earlier, Rev.9.01.51 and earlier, Rev.11.00.36 and earlier, Rev.11.01.31 and earlier, Rev.11.03.25 and earlier

Timeline

Official Publish: January 9th, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.